{"id":"CVE-2016-9136","details":"Artifex Software, Inc. MuJS before a0ceaf5050faf419401fe1b83acfa950ec8a8a89 allows context-dependent attackers to obtain sensitive information by using the \"crafted JavaScript\" approach, related to a \"Buffer Over-read\" issue.","modified":"2026-09-30T08:02:08.393884409Z","published":"2016-11-03T10:59:13.387Z","database_specific":{"unresolved_ranges":[{"vendor_product":"artifex:mujs","cpes":["cpe:2.3:a:artifex:mujs:*:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"2016-10-31"}],"source":"CPE_RANGE"}]},"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/94223"},{"type":"FIX","url":"http://bugs.ghostscript.com/show_bug.cgi?id=697244"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ccxvii/mujs","events":[{"introduced":"0"},{"fixed":"a0ceaf5050faf419401fe1b83acfa950ec8a8a89"}]}],"database_specific":{"vanir_signatures":[{"digest":{"length":1772,"function_hash":"239468669116027903225140499339312725867"},"id":"CVE-2016-9136-1c463b22","signature_type":"Function","signature_version":"v1","source":"https://github.com/ccxvii/mujs/commit/a0ceaf5050faf419401fe1b83acfa950ec8a8a89","target":{"file":"jslex.c","function":"lexescape"},"deprecated":false},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/ccxvii/mujs/commit/a0ceaf5050faf419401fe1b83acfa950ec8a8a89","target":{"file":"jslex.c"},"deprecated":false,"digest":{"line_hashes":["119764019118570011447641796189147322896","56841796762787324721027876861109556432","310541644262210412948094961550293014462","172903775110970999647545276254980753623"],"threshold":0.9},"id":"CVE-2016-9136-30ee571a"}],"vanir_signatures_modified":"2026-09-30T08:02:08Z","source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-9136.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}